Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Reauthenticating an NT 4.0 BDC

Posted on 2002-04-19
6
Medium Priority
?
287 Views
Last Modified: 2013-12-28
Fellow Experts:

I am currently managing a few fairly small military networks.  On one of my networks, I have an NT 4.0 domain set up with one PDC and one BDC.  The domain controllers had some issues and were seperated briefly.  The problem now is that the PDC does not trust the BDC.  Directory replication still occurs from the PDC and one can add / change users, etc on the PDC.  However, it is not possible to add users from the BDC.  It generates the error "There is no user session key for the specified logon session".  Also, errors 3210 and 7023 are present in the event log.  

This problem and resolution is described in Technet Article Q153719 "How to Re-Sync PDC/BDC Trust After Event IDs 3210 and 7023".  Basically, the password-protected channel has been broken and the account associated with the BDC's computer name (BDC$) is lo longer listed with the PDC.  However, the suggested resolution of renaming the computer name (even temporarily) is not feasible as the system is also an Exchange 5.5 server.  

Does anyone have any suggestions regarding how one might readd the computer name to the PDC (possibly a third party tool) so that we will not require a full rebuild of the NT Server and Exchange?  Any ideas would be greatly appreciated.

Sincerely,

Herb
0
Comment
Question by:schreib
  • 3
  • 2
6 Comments
 
LVL 11

Expert Comment

by:geoffryn
ID: 6960428
Have you tried manually resetting the secure channel?

http://support.microsoft.com/default.aspx?scid=kb;en-us;Q150518 
0
 

Author Comment

by:schreib
ID: 6962609
Geoffry:

Thanks for the feedback.  Actually, both netdom and nltest indicated that the secure channel was still valid.  However, the BDC can still not add users or complete similar tasks and presents the error "There is no user session key for the specified logon session."  Any other ideas would be greatly appreciated.

Herb
0
 
LVL 11

Accepted Solution

by:
geoffryn earned 1000 total points
ID: 6962958
Is the time correct on both servers?
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 

Author Comment

by:schreib
ID: 6963124
Geoffry:

You are the man!  The clock was off and that was the problem.  Thanks a ton!

Herb
0
 
LVL 11

Expert Comment

by:geoffryn
ID: 6963131
Glad to help.
0
 
LVL 5

Expert Comment

by:mbormann
ID: 9215117
Hey!

I cloned some Windows 2000 machines using Ghost 7.5 Corporate Edition, and when I attempt to join the NT 4 domain I consistently get the above error. I forgot to make sure that the SID was different, I did not use sysprep or Ghostwalker, but afterwards I used the NewSID tool from sysinternals.com. I also deleted machine account in PDC, restarted and recreated. I also tried naming the new computers to a completely new name not present in the Server Manager. BDC is almost always offline and is brought back up every few weeks or so. After spending two days, finally your comment "check teh time" solved m problem.

My time was set to GMT, apparently it doesn't affect machines which have already joined the domain, but affects the new machines joining the domain!

Thanks amigo!
0

Featured Post

Receive 1:1 tech help

Solve your biggest tech problems alongside global tech experts with 1:1 help.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Understanding the various editions available is vital when you decide to purchase Windows Server 2012. You need to have a basic understanding of the features and limitations in each edition in order to make a well-informed decision that best suits …
A few solutions to a problem some of us have been having when trying to add Hostgator email accounts to Outlook 2016 (will probably work with Outlook 2013 as well).
As developers, we are not limited to the functions provided by the VBA language. In addition, we can call the functions that are part of the Windows operating system. These functions are part of the Windows API (Application Programming Interface). U…
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
Suggested Courses

571 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question